Every governance claim EcoCloud makes is a cryptographically signed artifact — and checking it touches zero of our databases. A security reviewer can confirm the whole thing offline, against our public key, without a sales call or an NDA.
We’ll pull a real, freshly-signed governance result from the production API. Then you check the signature — right here, in your browser.
Each is a public endpoint that returns a real ES256-signed artifact. Append ?demo=1 for a sample, POST it back with {"action":"verify"} to confirm the signature — no auth, no DB.
A 5-dimension governance-maturity score — weakest-link level, signed. The board-report number, self-computed.
readiness?demo=1 →Verifies the stored hash-chain linkage and flags denials, reversals and overrides — a tamper check on the ledger itself.
forensic?demo=1 →A signed, cursor-paginated feed mapping every governed action to published SOC 2 / ISO 27001 / DORA control clauses.
ccm?demo=1 →Batch-evaluate actions against a constitution — verdict matrix + point-in-time (was it allowed at the time?), signed.
matrix?demo=1 →Finds the real holes — including the exact €/day unapproved exposure a threshold-with-no-cap permits.
analyze?demo=1 →Rate spikes, velocity bursts, denial spirals — explainable statistics (not a black-box model), signed.
anomaly?demo=1 →Real data residency, lawful basis, per-subprocessor transfer mechanism and an enforcement gate — signed posture.
jurisdiction?demo=1 →Exactly which vendors touch which data, where, under which DPA — a signed, machine-readable list.
/api/v1/subprocessors →Validated, versioned governance presets per vertical (BaFin, DORA, HIPAA, fintech OpRisk) — fork and enforce.
constitution-marketplace →A trust center that only lists strengths isn’t a trust center. Here is what our signatures do not mean.
The un-glamorous prerequisites — all real, all live.